A critical vulnerability in PuTTY versions 0.68 to 0.80 allows recovery of NIST P521 ECDSA private keys from signatures; users should revoke and replace affected keys. The vulnerability, assigned CVE-2024-31497, is fixed in the update identified by commit c193fe9848f.